The same second stage followed two different submissions

Patchstack says it first observed an exploitation attempt against WPC Product Bundles for WooCommerce on 4 October, then against Ninja Forms on 5 October. Both flaws allow an unauthenticated person to store malicious content. When that content is rendered in an administrator's browser, script runs with the site's administrative origin and can use the active session. The two entry points differ, but Patchstack found the same remote JavaScript payload behind both.

Attempts are not a victim count

Patchstack observed exploitation attempts in its telemetry and analysed the payload. That does not establish how many sites completed the infection chain or that every site with either plugin was compromised.

Fixing the XSS does not remove an installed backdoor

The retrieved payload used normal WordPress admin functions through the victim's browser to install a malicious plugin and create administrator access. Patchstack describes additional persistence: an account hidden from the Users screen, a backdoor login path, and a file manager available without authentication. This is why a clean plugin update is necessary but not sufficient if the poisoned content was already opened.

WPC Product Bundles through 8.6.6 and Ninja Forms through 3.15.3 are the vulnerable ranges in Patchstack's analysis. Check the latest maintainer release and changelog at update time; do not assume the first fixed release remains the newest available build.

Separate exposure, execution and persistence checks

  1. 1

    Identify affected installations. Inventory both plugins and the sites where orders or form submissions are reviewed by administrators.

  2. 2

    Update and verify. Install the current security-fixed releases, then verify the active plugin versions from the running site.

  3. 3

    Inspect the pre-update window. Review suspicious order metadata and form submissions, admin browser activity, plugin installation events and unexpected administrator creation.

  4. 4

    Hunt all persistence routes. Inspect must-use plugins, on-disk users and roles, unexpected login endpoints and unfamiliar file-manager code. Do not rely only on the wp-admin Users screen.

  5. 5

    Recover trust if execution occurred. Preserve evidence, remove malicious components, rotate credentials and WordPress security keys, and validate from a clean administrative session.

The browser was the bridge into privileged functions

  • Unauthenticated submission and authenticated execution are different phases of the same chain.
  • Check whether an administrator opened the affected order or form entry before treating the payload as successful.
  • Use Patchstack's current indicators as investigation leads, not as the only detection rule; infrastructure can change.